← 주요 프로젝트← Key projects

개인 프로젝트 · 주식 정보 프로토타입

PERSONAL PROJECT · STOCK INFORMATION PROTOTYPE

KOSTOCK

KOSTOCK

주식 시세와 뉴스, 관심 종목을 확인하는 Flutter 프로토타입입니다. Firebase 로그인과 외부 Q&A 챗봇을 연결했습니다.

A Flutter prototype for stock quotes, news and watchlists, with Firebase sign-in and an external Q&A chatbot.

FLUTTERFIREBASE AUTHPROVIDERREST APIALPHA VANTAGE
담당 작업Work involved

앱 구조 · 화면 · 인증 · REST 연동 · 상태 관리

App structure, screens, authentication, REST integration and state

현재 상태Current status

알파 버전 공개 · 실거래와 계좌 연동은 미구현

Alpha release published; live trading and brokerage account integration not implemented

01

프로젝트 개요

KOSTOCK이 다루는 사용자 흐름과 구현 범위

KOSTOCK은 주식 시세, 뉴스, 관심 종목과 Q&A를 확인하는 Flutter 프로토타입이다. 로그인, 주문 입력과 예시 자산 화면도 구현했다. 실제 증권 주문을 체결하거나 계좌를 연결하는 앱은 아니다.

사용자가 할 수 있는 일

  • 이메일·비밀번호, Google 또는 익명 방식으로 Firebase Auth에 로그인한다.
  • 홈과 현재가 탭에서 Alpha Vantage의 AAPL·MSFT 시세를 조회하고 새로고침한다.
  • 뉴스 탭에서 NEWS_SENTIMENT 피드를 읽고 관심 항목을 Provider 상태에 추가한다.
  • 주문·자동 감시 입력 폼과 예시 자산 화면을 통해 거래 서비스 흐름을 확인한다.
  • 외부 챗봇 엔드포인트에 질문을 보내고 대화 내역을 화면에서 확인한다.

담당 범위

Flutter 앱 구조, 다크 테마 화면, 여섯 개 탭, Firebase 초기화와 인증, REST 요청과 JSON 파싱, Provider 관심 상태, 챗봇 UI를 구현했다. Android·iOS·macOS 실행 설정과 앱 아이콘 구성도 저장소에 포함한다.

현재 상태

GitHub에 v0.0.1-alpha 릴리스가 공개된 학습·프로토타입 단계다. 실거래 체결, 계좌 연동, 영속 관심목록과 운영 수준 모니터링은 구현 범위가 아니다. 사용자 성과와 성능 수치는 측정되지 않음이다.

01

Project overview

User journey and implemented scope of KOSTOCK

KOSTOCK is a Flutter prototype for stock quotes, news, watchlists and Q&A. It also implements sign-in, order-entry forms and sample asset screens. It does not execute brokerage orders or connect real accounts.

User capabilities

  • Sign in through Firebase Auth with email and password, Google or an anonymous session.
  • Read and refresh AAPL and MSFT quotes from Alpha Vantage on the home and current-price screens.
  • Browse the NEWS_SENTIMENT feed and add items to an in-memory Provider watchlist.
  • Explore order, automatic-monitoring and sample asset interfaces.
  • Send questions to an external chatbot endpoint and view the in-session conversation.

Ownership

The work covers Flutter structure, dark-theme screens, six tabs, Firebase initialization and authentication, REST requests and JSON parsing, Provider state and chatbot UI. Android, iOS and macOS runner configuration is also present.

Current status

The repository publishes a v0.0.1-alpha learning prototype. Brokerage execution, account integration, persistent watchlists and production observability are outside the implemented scope. User outcomes and performance are not measured.

02

아키텍처

Flutter 화면, 인증, 상태와 외부 API의 상세 실행 경계

1. 부트스트랩과 인증 경계

main.dart가 Flutter binding과 Firebase를 초기화하고 MultiProvider에 InterestProvider를 주입한다. 첫 화면인 LoginPage는 Firebase Auth를 직접 호출해 이메일, Google, 익명 자격 증명을 처리한다. 인증 성공 뒤에만 MainPage로 교체되며, MY 자산 화면의 로그아웃과 계정 삭제도 같은 Firebase 세션을 사용한다.

2. 화면·상태 경계

MainPage의 BottomNavigationBar가 홈, 뉴스, 관심종목, 주문, MY 자산, 현재가 여섯 화면을 전환한다. 화면은 IndexedStack 안에 유지되므로 탭 이동 때 위젯 상태가 사라지지 않는다. 공유되는 관심 항목은 ChangeNotifier 기반 InterestProvider가 관리하지만 디스크나 Firestore에는 저장하지 않아 앱 재시작 시 초기화된다.

3. 시세·뉴스 읽기 흐름

홈은 GLOBAL_QUOTE, 현재가 화면은 TIME_SERIES_INTRADAY, 뉴스는 NEWS_SENTIMENT 요청을 Flutter 클라이언트에서 Alpha Vantage로 직접 보낸다. 각 화면이 응답 코드를 확인하고 JSON을 화면 모델로 바로 변환한다. 네트워크 예외는 loading 종료와 오류 상태로 흡수하지만 공통 API client, 캐시, 재시도 정책은 분리돼 있지 않다.

4. 챗봇 흐름

XsChatbotPage는 질문을 외부 /question 엔드포인트에 JSON POST로 전송하고 template.outputs[0].simpleText.text 응답을 채팅 목록에 추가한다. 요청 중 spinner와 오류 문자열을 표시하지만 대화는 메모리에만 남고 엔드포인트 장애 시 다른 공급자로 전환하지 않는다.

5. 신뢰 경계와 실패 처리

Firebase는 신원 경계이고, Alpha Vantage와 챗봇 서버는 별도 외부 장애 경계다. 현재 API 호출과 키가 클라이언트 코드에 결합돼 있으므로 운영 전에는 서버 프록시, 비밀 관리, rate limit과 구조화된 오류 모델이 필요하다. 주문·자산 화면은 금융기관과 연결되지 않은 UI 시뮬레이션으로 실제 금전 거래를 만들지 않는다.

6. 상태·데이터 소유권

Firebase가 인증 세션을, Provider가 관심 종목을, 각 탭 State가 화면 선택과 응답을 소유한다. 금융기관 원장이나 주문 상태 저장소는 미구현이며 앱의 자산·주문 화면은 로컬 표현 상태일 뿐이다.

7. 성능·외부 API 복구

시세·뉴스 호출은 rate limit과 네트워크 지연의 영향을 받는다. 요청 중복 제거, symbol별 짧은 cache, timeout·retry budget과 오래된 데이터 표시가 필요하며 챗봇 장애는 시세 탐색 기능과 격리되어야 한다.

8. 보안·관측·기술 부채

API 키와 챗봇 endpoint를 클라이언트에서 제거하고 TLS·입력 길이·응답 schema를 검증해야 한다. 현재 통합 telemetry와 오류 분류는 미구현이며 실제 금융 정확도·지연 지표는 측정되지 않았다.

02

Architecture

Detailed runtime boundaries across Flutter, authentication, state and external APIs

1. Bootstrap and identity boundary

main.dart initializes the Flutter binding and Firebase, then injects InterestProvider through MultiProvider. LoginPage calls Firebase Auth directly for email, Google and anonymous credentials. Successful authentication replaces the route with MainPage; logout and account deletion use the same Firebase session boundary.

2. Presentation and state boundary

MainPage switches among home, news, watchlist, order, assets and current-price screens with a BottomNavigationBar. An IndexedStack retains those widgets across tab changes. Shared watchlist entries live in a ChangeNotifier-based InterestProvider, but no disk or Firestore adapter persists them, so a process restart resets the list.

3. Quote and news read path

Home calls GLOBAL_QUOTE, the quote screen calls TIME_SERIES_INTRADAY, and news calls NEWS_SENTIMENT directly from the Flutter client. Each screen checks the HTTP status and maps JSON straight into view state. Exceptions end loading and expose a local error path, but there is no shared API client, cache or retry policy.

4. Chat path

XsChatbotPage sends a JSON POST to an external /question endpoint and reads template.outputs[0].simpleText.text into the in-memory chat list. The view exposes loading and error text, but conversation history is not persisted and there is no provider fallback.

5. Trust and failure boundaries

Firebase owns identity; Alpha Vantage and the chatbot server are independent availability boundaries. API calls and credentials are currently coupled to client code, so a production version would require a server proxy, secret management, rate limiting and a structured error contract. Order and asset screens are simulations and never create financial transactions.

6. State and data ownership

Firebase owns the identity session, Provider owns the watchlist, and each tab State owns selection and response data. A broker ledger or persisted order state is missing; portfolio and order screens are local presentation state only.

7. Performance and external-API recovery

Quote and news calls are exposed to rate limits and network latency. Request deduplication, short symbol caches, timeout and retry budgets, and stale-data labeling are required; chatbot failure should remain isolated from market exploration.

8. Security, observability and debt

API keys and the chatbot endpoint should move out of the client, with TLS, input length and response-schema validation. Unified telemetry and error classification are missing. Financial accuracy and latency metrics have not been measured.

구조와 데이터 흐름

Structure and data flow

도식을 누르면 크게 볼 수 있습니다. 구현 여부와 참고한 코드도 표시했습니다.

Select a diagram to enlarge it. Labels show implementation status and source files.

01
시스템 컨텍스트 · 신뢰 경계System context · trust boundaries투자 정보 사용자와 Firebase·시세 API·챗봇의 경계입니다.Boundaries between market-information users, Firebase, quote APIs and chatbot.
선택하면 전체 화면에서 세부 구조와 근거 번호를 볼 수 있습니다.Select to inspect the structure and evidence references full screen.
02
런타임 · 모듈 · 상태 소유권Runtime · modules · state ownershipFlutter 셸, Provider 상태, 인증·네트워크 클라이언트를 분해합니다.Decomposes Flutter shell, Provider state, identity and network clients.
선택하면 전체 화면에서 세부 구조와 근거 번호를 볼 수 있습니다.Select to inspect the structure and evidence references full screen.
03
핵심 사용자 흐름 · 요청 시퀀스Core user flow · request sequence종목 조회·즐겨찾기·챗봇 질문이 화면에 돌아오는 흐름입니다.Flow returning quote, favorite and chatbot requests to the UI.
선택하면 전체 화면에서 세부 구조와 근거 번호를 볼 수 있습니다.Select to inspect the structure and evidence references full screen.
04
데이터 · 배포 · 보안 · 복구Data · delivery · security · recoveryFirebase 구성, API 의존성, 플랫폼 빌드와 오류 경계를 표시합니다.Shows Firebase configuration, API dependencies, platform builds and failure boundaries.
선택하면 전체 화면에서 세부 구조와 근거 번호를 볼 수 있습니다.Select to inspect the structure and evidence references full screen.
03

기술 결정

KOSTOCK의 선택 이유, 대안과 감수한 비용

Flutter로 여러 플랫폼을 한 번에 구성

Android 중심 프로토타입을 빠르게 만들면서 iOS·macOS 러너도 유지하기 위해 Flutter를 사용했다. 네이티브별 최적화보다 한 코드베이스에서 화면과 네트워크 흐름을 검증하는 쪽을 선택했다.

인증은 Firebase에 위임

직접 세션 서버를 만들지 않고 이메일, Google, 익명 로그인과 계정 삭제를 Firebase Auth에 맡겼다. 구현 범위는 줄지만 Firebase 설정 파일과 플랫폼별 OAuth 구성이 배포 전제에 포함된다.

탭은 IndexedStack으로 유지

탭을 매번 재생성하는 대신 여섯 화면을 유지해 이동 후 상태를 보존한다. 전환 경험은 단순해지지만 모든 탭 인스턴스를 함께 유지하므로 화면이 커지면 메모리와 초기 작업을 별도로 최적화해야 한다.

관심목록은 Provider 메모리 상태

작은 범위에서 상태 변화를 학습하고 화면 간 공유하기 위해 ChangeNotifier를 사용했다. 저장 계층을 만들지 않아 구현은 명확하지만 앱 종료 뒤 데이터가 남지 않는다.

외부 API를 클라이언트에서 직접 호출

시세·뉴스와 챗봇을 빠르게 연결하는 대신 키 보호, 응답 정규화, rate limit, retry를 중앙화하지 못했다. 운영 제품이라면 백엔드 프록시가 더 안전하지만 이 버전은 통합 프로토타입의 범위를 택했다.

03

Decisions

Why KOSTOCK made its current choices and what they cost

Use Flutter across platform runners

Flutter keeps Android, iOS and macOS presentation in one codebase while the prototype validates screens and networking. This favors delivery speed over platform-specific optimization.

Delegate identity to Firebase

Firebase Auth supplies email, Google and anonymous sessions without a custom identity server. It narrows the implementation but makes Firebase configuration and platform OAuth part of deployment.

Retain tabs with IndexedStack

Six screens remain alive instead of being rebuilt on every switch. Navigation state is predictable, while larger future screens would require control over retained memory and startup work.

Keep watchlists in Provider memory

ChangeNotifier makes cross-screen state explicit at small scale. The absence of a persistence adapter keeps the prototype simple but loses watchlists when the application exits.

Call external APIs from the client

Direct calls made quote, news and chatbot integration quick. The cost is that key protection, response normalization, rate limiting and retry are not centralized. A backend proxy is the safer production alternative.

04

검증과 한계

확인 가능한 시나리오와 아직 증명되지 않은 부분

확인 가능한 수동 시나리오

  1. Firebase 설정이 있는 환경에서 이메일·Google·익명 로그인이 메인 화면으로 연결되는지 확인한다.
  2. 하단 여섯 탭을 왕복해 각 화면 상태가 IndexedStack 안에서 유지되는지 확인한다.
  3. 시세·뉴스 API의 성공, 빈 응답, 제한 초과와 네트워크 실패 상태를 각각 확인한다.
  4. 뉴스 관심 버튼이 Provider 목록과 동기화되고 앱 재시작 뒤 초기화되는 현재 계약을 확인한다.
  5. 챗봇 응답 성공, 비정상 응답 구조, endpoint timeout을 확인한다.
  6. 로그아웃과 계정 삭제 뒤 인증 화면으로 돌아가는지 확인한다.

자동 검증 상태

저장소에는 Flutter lint 설정과 플랫폼 Runner 테스트 골격이 있지만, 인증·데이터·주문 흐름을 보장하는 Dart 단위 테스트나 통합 테스트는 확인되지 않는다. 따라서 회귀 안정성, API 성공률, 프레임 성능과 접근성 결과는 측정되지 않음이다.

알려진 한계

  • 시세 심볼과 일부 홈 콘텐츠가 고정돼 있으며 한국 시장 전체 탐색을 제공하지 않는다.
  • 관심목록, 채팅, 주문 입력은 영속 저장되지 않는다.
  • 클라이언트 직접 API 호출은 키 노출과 호출 제한에 취약하다.
  • 외부 챗봇 endpoint와 Alpha Vantage 장애가 앱 기능에 직접 영향을 준다.
  • 주문과 자산은 예시 UI이며 증권 계좌나 체결 시스템과 연결되지 않는다.
04

Validation and limits

Reproducible scenarios and behavior that remains unproven

Reproducible manual scenarios

  1. With valid Firebase configuration, verify that email, Google and anonymous sessions reach the main shell.
  2. Move through all six tabs and confirm that IndexedStack retains each screen’s state.
  3. Exercise quote and news success, empty response, rate-limit and offline paths.
  4. Toggle a news watch item, verify Provider synchronization and confirm the current reset-on-restart contract.
  5. Exercise chatbot success, malformed response and endpoint timeout.
  6. Verify that logout and account deletion return to authentication.

Automated evidence

The repository includes Flutter lint configuration and platform Runner test skeletons, but no confirmed Dart unit or integration suite for identity, data or order flows. Regression stability, API success rate, frame performance and accessibility are therefore not measured.

Known limits

  • Quote symbols and parts of the home content are fixed rather than a complete Korean-market universe.
  • Watchlists, chat and order input are not persisted.
  • Direct client API calls expose credential and rate-limit risks.
  • Alpha Vantage and the chatbot endpoint directly affect feature availability.
  • Order and asset views are examples, not brokerage or execution integrations.
05

로드맵

완료, 개선, 계획과 범위 제외 항목

완료

  • Flutter 다크 테마와 여섯 개 주요 탭
  • Firebase 이메일·Google·익명 로그인과 계정 관리
  • Alpha Vantage 시세·뉴스 읽기
  • Provider 관심 항목 공유
  • 주문·자동 감시·자산 프로토타입 화면
  • 외부 Q&A 챗봇과 alpha 릴리스

우선 개선

  • API 키와 외부 호출을 서버 프록시 뒤로 이동
  • 공통 API client, timeout, retry와 오류 모델 도입
  • 관심목록과 사용자 설정 영속화
  • repository/service/view-model 경계로 화면의 직접 네트워크 호출 분리
  • 인증·파싱·상태·탭 이동 테스트 추가

이후 계획

  • 검색 가능한 종목 universe와 시장별 symbol mapping
  • 접근성 label, 큰 글자와 스크린 리더 검증
  • 캐시와 offline last-known 데이터
  • 운영 endpoint 상태 관측과 개인정보 처리 문서

범위에서 제외

실제 주문 체결, 투자 자문, 수익 보장과 증권 계좌 보관은 이 프로토타입의 범위가 아니다. 해당 기능은 금융 규제, 보안 심사와 별도 서버 설계 없이는 추가하지 않는다.

05

Roadmap

Completed, next, planned and explicitly excluded work

Completed

  • Flutter dark theme and six primary tabs
  • Firebase email, Google and anonymous authentication
  • Alpha Vantage quote and news reads
  • Provider watchlist sharing
  • Order, monitoring and asset prototype screens
  • External Q&A chatbot and alpha release

Priority improvements

  • Move API credentials and calls behind a server proxy
  • Introduce a shared client, timeout, retry and error contract
  • Persist watchlists and user settings
  • Separate direct view networking into repository, service and view-model boundaries
  • Add tests for authentication, parsing, state and navigation

Later work

  • Searchable symbol universe and market mapping
  • Accessibility labels, large text and screen-reader validation
  • Cache and offline last-known data
  • Endpoint observability and privacy documentation

Out of scope

Real order execution, investment advice, guaranteed returns and brokerage custody are not part of this prototype. They require financial compliance, security review and a separate server architecture.

확대 보기Expanded view

도식을 좌우로 이동하거나 확대해 세부 흐름을 확인할 수 있습니다.

Pan or zoom the diagram to inspect the detailed flow.